Headline
GHSA-2xxc-73fv-36f7: llama-index vulnerable to arbitrary code execution
An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the exec
parameter in PandasQueryEngine function.
llama-index vulnerable to arbitrary code execution
Critical severity GitHub Reviewed Published Aug 15, 2023 to the GitHub Advisory Database • Updated Aug 15, 2023
Related news
CVE-2023-39662: [Bug]: Prompt injection which will lead to RCE · Issue #7054 · jerryjliu/llama_index
An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.